Security & data
Your data stays in Dubai. Your rules bind every AI agent.
Security and data protection are part of the design: where data is hosted, what an AI may see and do, and what is kept on record.
At a glance
Hosted in Dubai. All customer data is hosted on Microsoft Azure in the UAE North region, in Dubai.
Pseudonymised AI requests. AI models only receive pseudonymised data and never KYC data. The provider stores nothing and trains on nothing.
Permissions before the model. Every data access and every action of an AI agent is checked against its permissions first.
People decide. Money, signatures, AML and HR decisions always stay with people.
Every step on record. An append-only, hash-chained evidence log with an export that can be verified independently.
Hosting
Where your data is hosted
All customer data is hosted in Dubai. Only two services run in the EU, and neither stores customer data.
Application server and background jobs
DubaiLocation: Microsoft Azure UAE North, Dubai
Protection: Every request and job carries the brokerage it belongs to.
Database (PostgreSQL)
DubaiLocation: Microsoft Azure UAE North, Dubai
Protection: Row-level security separates every brokerage.
File storage
DubaiLocation: Microsoft Azure UAE North, Dubai
Protection: File paths carry the brokerage; identity documents sit in an encrypted vault.
Encryption keys and secrets
DubaiLocation: Azure Key Vault with hardware security module, Dubai
Protection: Central key management; no secrets in code.
Backups
DubaiLocation: Dubai; a second copy in Abu Dhabi once that region opens for us
Protection: Encrypted; the same residency rules as live data.
AI models
EULocation: Amazon Bedrock, Frankfurt (EU)
Protection: Pseudonymised input only, zero data retention, no training.
System e-mail
EULocation: Amazon SES, Frankfurt (EU)
Protection: Send only, nothing stored.
Public website
WebsiteLocation: Vercel
Protection: Never receives customer data.
Our staging environment has run in Dubai since 28 September 2026. A separate production environment in Dubai follows with the first pilot brokerage. Real customer data is processed only after a legal review of the set-up.
Data flow
How data flows
Customer data stays inside the platform in Dubai. What leaves it is limited to pseudonymised AI requests and outgoing system e-mail.
Your brokerage
Owners, brokers and staff in the browser and the broker app
HTTPS
Microsoft Azure UAE North · Dubai
- Application and jobs
- Database
- Files
- Keys (HSM)
- Backups
AI gateway
Checks permissions, pseudonymises, logs every call
Pseudonymised only
EU · Frankfurt
AI model
Amazon Bedrock: pseudonymised input, zero retention, no training
System e-mail
Amazon SES: send only, nothing stored
Public website
Vercel: no customer data. The sign-up form sends directly from the browser to Dubai.
AI governance
How we govern AI
AI agents in Zolia work like members of the team, with clear rules, not like a black box.
Permissions before the model
Every data access and tool call of an AI agent is checked against its permissions. Agents do not inherit the rights of the person who approved them.
AI gateway
KYC data never reaches a model, and confidential data only in pseudonymised form. Only models with zero data retention are used, under a residency policy per brokerage. Every call is logged with purpose, model, region, cost and the responsible person.
Autonomy set by the brokerage
Levels per agent and type of action, with an emergency stop. Money actions are capped; signatures, payouts and AML decisions always stay with people.
Quality before release
An evaluation suite for every AI function, an output check before every AI draft, and defences against prompt injection tested in English and Gulf Arabic.
AML by design
Only the compliance agent can read the AML area, and it has no client channel. Other agents see only “compliance hold”, which prevents tipping-off.
Security controls
Built in and covered by automated tests
Tenant isolation
PostgreSQL row-level security separates every brokerage; files and background jobs carry the brokerage they belong to.
Access and identity
Sign-in with one-time codes and passkeys; permissions are checked for every action, by people and by AI agents.
Audit and evidence
An audit log records every change and stores confidential values only as keyed hashes. Key events go into an append-only, hash-chained evidence log with integrity checks, alarms and an independently verifiable export.
Encrypted vaults
Identity documents sit in an encrypted vault. Third-party credentials of a brokerage, for example DLD or portal access, are stored only encrypted, with no read path for people, the API or exports.
Retention and deletion
Retention classes with deadlines, legal hold and proof of deletion.
Secure development
Automated tests run on every change. Code, dependencies, containers and secrets are scanned, and critical findings block a release.
Data protection
Data protection principles
- Built for the UAE data protection law (Federal Decree-Law No. 45 of 2021): only the data a feature needs, used for its stated purpose.
- Zolia staff see a brokerage's data only with that brokerage's time-limited, logged approval. Emergency access is possible only with immediate notice.
- No AI training on one brokerage's content for other brokerages without opt-in, and never on WhatsApp content.
- A consent register governs all client communication.
Next steps
What comes next
- A UAE law firm reviews terms, data processing and data residency before the pilot.
- An external penetration test before production.
- ISO 27001 at a later stage.